DKIM
Short definition
DKIM attaches a cryptographic signature to outgoing email that proves the message was not altered in transit.
DKIM, DomainKeys Identified Mail, has the sending server attach an encrypted signature to an outgoing email. The receiving server verifies that signature against a public key published in the domain's DNS.
If the signature holds, the message has not been altered since it was sent, tampering with the content along the way becomes practically impossible. SPF verifies the sending server, DKIM verifies the message itself.
Setting up DKIM usually means adding a few DNS records from the email provider's panel, technically simple but an easy step to skip.
A DKIM record appears in DNS under a name like selector._domainkey.example.com, the selector at the front is usually a short code the email provider assigns, and more than one selector can be active at once. Looking at the DKIM-Signature line in an incoming email's headers shows exactly which selector signed it and whether that verification passed.
Why it matters
Email sent without DKIM looks less trustworthy to large providers and delivery rates drop. One small DNS setting is often what decides whether a business email lands in the inbox or in spam.
Illustrative example
A spa chain noticed booking confirmation emails arriving late or not at all, the cause turned out to be a DKIM record that had never been set up.
